Implement DPDP & privacy compliance across customer and vendor journeys - via a single platform
Privacy-first companies have already started using Consentin
















DPDP Rules are here - comply fast with Consentin
Collect and manage DPDP-compliant consent across customer journeys
.webp)



Manage and respond to rights requests
Use
to identify and
classify personal data




Automate third party risk assessments and breach notifications
All modules in Consentin
Consent Management
Collect and manage consent across channels.
Privacy Centre
Manage privacy rights and revocation requests.
Consentin Lens
Run discovery and mapping across structured and unstructured systems.
Unified Assessments
Conduct DPIA, PIA and third-party risk assessments.
Retention & Deletion
Automate data retention and deletion across internal and third-party systems.
Breach Notification
Notify the Board and affected customers within the deadline.
Cookie Consent
Deploy compliant cookie banners across sites within weeks.
Auditable Logs & Records
Maintain immutable consent, request and deletion records with full audit trail.
Criteria
Consentin (SaaS/Cloud)
Consentin (On Prem)
We have an irresistible starter offer for you
3000 DPDP-compliant consent collections/month — ₹0 (forever)
With our Starter Pack, you can collect 3,000 consents per month at ₹0—forever.
If your volumes are ≤ 3,000 / month, run DPDP end-to-end at no cost.
If your volumes are > 3,000 / month, use this to run a free live pilot before you buy.
Sign up for a DPDP Demo to start using Consentin
Frequently asked questions
Under the DPDP Act, a Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact to enable a user to give, manage, review, and withdraw their consent through an accessible, transparent, and interoperable platform.
Registration for Consent Managers opens on 13th November 2026. There are no registered Consent Managers in India yet.
A Data Processor is an entity that processes data on behalf of a Data Fiduciary, acting under its instructions. It does not determine why and how the data is processed.
Under the DPDP Act, you must take user consent when processing digital personal data or physical personal data digitized subsequently, unless the processing falls under specific exemptions provided by the Act. Key scenarios requiring user consent include:
- Collecting Personal Data: when collecting personal data for any purpose.
- Sharing Data with Third Parties: before sharing user data with external entities.
- Using Data for New Purposes: if the purpose of processing changes from what was initially communicated.
- Retention Beyond Purpose: if data needs to be retained for reasons other than the original purpose of collection.
Yes, the DPDP Rules were notified on 13th November 2025, bringing the DPDP Act into force. The Rules introduce different timelines for different provisions.
Data Fiduciaries have been granted 18 months to comply with the Act and the Rules. This window ends on 13th May 2027.
Penalties under the DPDP Act can go up to ₹250 crore per violation.
To know more about penalties for different DPDP violations, see our blog.
A DPDP compliance platform is software that helps a business manage its obligations under the DPDP Act, including data discovery, data mapping, collecting consent, sending notices, handling data requests, and managing retention and deletion, all in one place.
A data breach is any unauthorized access, disclosure, alteration, or loss of personal data that puts its safety at risk.
If a breach happens, the Data Fiduciary must inform the Data Protection Board and each affected Data Principal. The Rules require this without delay, followed by a detailed report to the Board within 72 hours. To know more about breach notification under the DPDP Act, see our blog.
There are several key differences:
- Legal basis: GDPR allows six lawful bases for processing data; DPDP allows only two: consent and certain legitimate uses.
- Penalties: GDPR fines are a percentage of global turnover; DPDP fines are fixed rupee amounts, capped at ₹250 crore per instance.
- Officer requirement: GDPR mandates a Data Protection Officer for most processors; DPDP doesn't require one for every business.
That's why a GDPR-compliant platform may not be the right choice if you're looking for DPDP compliance. You need a platform built specifically for it.